VLDB 2026 Research / reviewers in the wild / expert
Alberto Giaretta 0001
dblp:175/5515-1
· DBLP profile ↗
11ranked-venue papers
3as first author
6since 2021 · last 2025
0000-0001-9293-7711ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 4 · 1 first-author · 4 since 2021Security and privacy · 4 · 2 first-author · 1 since 2021Software engineering, systems software and programming languages · 2 · 1 since 2021Artificial intelligence and machine learning · 1Systems, architecture and hardware · 1Applied, interdisciplinary, general and emerging computing · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Differential Area Analysis for Ransomware: Attacks, Countermeasures, and LimitationsabstractCrypto-ransomware attacks have been a growing threat over the last few years. The goal of every ransomware strain is encrypting user data, such that attackers can later demand users a ransom for unlocking their data. To maximise their earning chances, attackers equip their ransomware with strong encryption which produce files with high entropy values. Davies et al. proposed Differential Area Analysis (DAA), a technique that analyses files headers to differentiate compressed, regularly encrypted, and ransomware-encrypted files. In this paper, first we propose three different attacks to perform malicious header manipulation and bypass DAA detection. Then, we propose three countermeasures, namely 2-Fragments (2F), 3-Fragments (3F), and 4-Fragments (4F), which can be applied equally against each of the three attacks we propose. We conduct a number of experiments to analyse the ability of our countermeasures to detect ransomware-encrypted files, whether implementing our proposed attacks or not. Last, we test the robustness of our own countermeasures by analysing the performance, in terms of files per second analysed and resilience to extensive injection of low-entropy data. Our results show that our detection countermeasures are viable and deployable alternatives to DAA. Marco Venturini, Francesco Freda, Emanuele Miotto, Mauro Conti, Alberto Giaretta 0001 |
IEEE Trans. Dependable Secur. Comput. | 5 |
| 2023 | Devils in the Clouds: An Evolutionary Study of Telnet Bot LoadersabstractOne of the innovations brought by Mirai and its derived malware is the adoption of self-contained loaders for infecting IoT devices and recruiting them in botnets. Functionally decoupled from other botnet components and not embedded in the payload, loaders cannot be analysed using conventional approaches that rely on honeypots for capturing samples. Different approaches are necessary for studying the loaders evolution and defining a genealogy. To address the insufficient knowledge about loaders' lineage in existing studies, in this paper, we propose a semantic-aware method to measure, categorize, and compare different loader servers, with the goal of highlighting their evolution, independent from the payload evolution. Leveraging behavior-based metrics, we cluster the discovered loaders and define eight families to determine the genealogy and draw a homology map. Our study shows that the source code of Mirai is evolving and spawning new botnets with new capabilities, both on the client side and the server side. In turn, shedding light on the infection loaders can help the cybersecurity community to improve detection and prevention tools. Yuhui Zhu, Qiben Yan 0001, Shanshan Wang 0003, Alberto Giaretta 0001, Enlong Li, Lizhi Peng, Mauro Conti |
ICC | 5 |
| 2022 | A PLS-HECC-based device authentication and key agreement scheme for smart home networks
Jamshid Pirayesh, Alberto Giaretta 0001, Mauro Conti, Parviz Keshavarzi |
Comput. Networks | 2 |
| 2022 | A machine learning-based approach to detect threats in bio-cyber DNA storage systems
Federico Tavella, Alberto Giaretta 0001, Mauro Conti, Sasitharan Balasubramaniam |
Comput. Commun. | 2 |
| 2022 | S×C4IoT: A Security-by-contract Framework for Dynamic Evolving IoT DevicesabstractThe Internet of Things (IoT) revolutionised the way devices, and human beings, cooperate and interact. The interconnectivity and mobility brought by IoT devices led to extremely variable networks, as well as unpredictable information flows. In turn, security proved to be a serious issue for the IoT, far more serious than it has been in the past for other technologies. We claim that IoT devices need detailed descriptions of their behaviour to achieve secure default configurations, sufficient security configurability, and self-configurability. In this article, we propose S×C4IoT, a framework that addresses these issues by combining two paradigms: Security by Contract (S×C) and Fog computing. First, we summarise the necessary background such as the basic S×C definitions. Then, we describe how devices interact within S×C4IoT and how our framework manages the dynamic evolution that naturally result from IoT devices life-cycles. Furthermore, we show that S×C4IoT can allow legacy S×C-noncompliant devices to participate with an S×C network, we illustrate two different integration approaches, and we show how they fit into S×C4IoT. Last, we implement the framework as a proof-of-concept. We show the feasibility of S×C4IoT and we run different experiments to evaluate its impact in terms of communication and storage space overhead. Alberto Giaretta 0001, Nicola Dragoni, Fabio Massacci |
ACM Trans. Sens. Networks | 1 |
| 2021 | Microservices: Migration of a Mission Critical SystemabstractAn increasing interest is growing around the idea of microservices and the promise of improving scalability when compared to monolithic systems. Several companies are evaluating pros and cons of a complex migration. In particular, financial institutions are positioned in a difficult situation due to the economic climate and the appearance of agile competitors that can navigate in a more flexible legal framework and started their business since day one with more agile architectures and without being bounded to outdated technological standard. In this paper, we present a real world case study in order to demonstrate how scalability is positively affected by re-implementing a monolithic architecture (MA) into a microservices architecture (MSA). The case study is based on theFX Coresystem, a mission critical system of Danske Bank, the largest bank in Denmark and one of the leading financial institutions in Northern Europe. The technical problem that has been addressed and solved in this paper is the identification of a repeatable migration process that can be used to convert a real world Monolithic architecture into a Microservices architecture in the specific setting of financial domain, typically characterized by legacy systems and batch-based processing on heterogeneous data sources. Manuel Mazzara, Nicola Dragoni, Antonio Bucchiarone, Alberto Giaretta 0001, Stephan Thordal Larsen, Schahram Dustdar |
IEEE Trans. Serv. Comput. | 4 |
| 2020 | BitFlow: Enabling real-time cash-flow evaluations through blockchainabstractSummary Disbursement registration has always been a cumbersome, opaque, and inefficient process, up to the point that most businesses perform cash‐flow evaluations only on a quarterly basis. We believe that automatic cash‐flow evaluations can actively mitigate these issues. In this paper, we present BitFlow, a blockchain‐based architecture that provides complete cash‐flow transparency and diminishes the probability of undetected frauds through the BitKrone, a non‐volatile cryptocurrency that maps to the Danish Krone (DKK). We show that confidentiality can be effectively achieved on a permissionless blockchain using Zero‐Knowledge proofs, ensuring verifiable transfers and automatic evaluations. Furthermore, we discuss several experiments to evaluate our proposal, in particular, the impact that confidential transactions have on the whole system, in terms of responsiveness and from an economical expenditure perspective. Lasse Herskind, Alberto Giaretta 0001, Michele De Donno, Nicola Dragoni |
Concurr. Comput. Pract. Exp. | 2 |
| 2018 | Adding Salt to Pepper: A Structured Security Assessment over a Humanoid RobotabstractThe rise of connectivity, digitalization, robotics, and artificial intelligence (AI) is rapidly changing our society and shaping its future development. During this technological and societal revolution, security has been persistently neglected, yet a hacked robot can act as an insider threat in organizations, industries, public spaces, and private homes. In this paper, we perform a structured security assessment of Pepper, a commercial humanoid robot. Our analysis, composed by an automated and a manual part, points out a relevant number of security flaws that can be used to take over and command the robot. Furthermore, we suggest how these issues could be fixed, thus, avoided in the future. The very final aim of this work is to push the rise of the security level of IoT products before they are sold on the public market. Alberto Giaretta 0001, Michele De Donno, Nicola Dragoni |
ARES | 1 |
| 2018 | DDoS-Capable IoT Malwares: Comparative Analysis and Mirai InvestigationabstractThe Internet of Things (IoT) revolution has not only carried the astonishing promise to interconnect a whole generation of traditionally “dumb” devices, but also brought to the Internet the menace of billions of badly protected and easily hackable objects. Not surprisingly, this sudden flooding of fresh and insecure devices fueled older threats, such as Distributed Denial of Service (DDoS) attacks. In this paper, we first propose an updated and comprehensive taxonomy of DDoS attacks, together with a number of examples on how this classification maps to real-world attacks. Then, we outline the current situation of DDoS-enabled malwares in IoT networks, highlighting how recent data support our concerns about the growing in popularity of these malwares. Finally, we give a detailed analysis of the general framework and the operating principles of Mirai, the most disruptive DDoS-capable IoT malware seen so far. Michele De Donno, Nicola Dragoni, Alberto Giaretta 0001, Angelo Spognardi |
Secur. Commun. Networks | 3 |
| 2017 | Analysis of DDoS-Capable IoT MalwaresabstractThe Internet of Things (IoT) revolution promises to make our lives easier by providing cheap and always connected smart embedded devices, which can interact on the Internet and create added values for human needs.But all that glitters is not gold.Indeed, the other side of the coin is that, from a security perspective, this IoT revolution represents a potential disaster.This plethora of IoT devices that flooded the market were very badly protected, thus an easy prey for several families of malwares that can enslave and incorporate them in very large botnets.This, eventually, brought back to the top Distributed Denial of Service (DDoS) attacks, making them more powerful and easier to achieve than ever.This paper aims at provide an up-to-date picture of DDoS attacks in the specific subject of the IoT, studying how these attacks work and considering the most common families in the IoT context, in terms of their nature and evolution through the years.It also explores the additional offensive capabilities that this arsenal of IoT malwares has available, to mine the security of Internet users and systems.We think that this up-to-date picture will be a valuable reference to the scientific community in order to take a first crucial step to tackle this urgent security issue. Angelo Spognardi, Michele De Donno, Nicola Dragoni, Alberto Giaretta 0001 |
FedCSIS | 4 |
| 2016 | Security Vulnerabilities and Countermeasures for Target Localization in Bio-NanoThings Communication NetworksabstractThe emergence of molecular communication has provided an avenue for developing biological nanonetworks. Synthetic biology is a platform that enables reprogramming cells, which we refer to as Bio-NanoThings, that can be assembled to create nanonetworks. In this paper, we focus on specific Bio-NanoThings, i.e, bacteria, where engineering their ability to emit or sense molecules can result in functionalities, such as cooperative target localization. Although this opens opportunities, e.g., for novel healthcare applications of the future, this can also lead to new problems, such as a new form of bioterrorism. In this paper, we investigate the disruptions that malicious Bio-NanoThings (M-BNTs) can create for molecular nanonetworks. In particular, we introduce two types of attacks: blackhole and sentry attacks. In blackhole attack M-BNTs emit attractant chemicals to draw-in the legitimate Bio-NanoThings (L-BNTs) from searching for their target, while in the sentry attack, the M-BNTs emit repellents to disperse the L-BNTs from reaching their target. We also present a countermeasure that L-BNTs can take to be resilient to the attacks, where we consider two forms of decision processes that includes Bayes' rule as well as a simple threshold approach. We run a thorough set of simulations to assess the effectiveness of the proposed attacks as well as the proposed countermeasure. Our results show that the attacks can significantly hinder the regular behavior of Bio-NanoThings, while the countermeasures are effective for protecting against such attacks. Alberto Giaretta 0001, Sasitharan Balasubramaniam, Mauro Conti |
IEEE Trans. Inf. Forensics Secur. | 1 |